Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78961

CVE-2026-78961: Google Chrome Authorization Bypass Vulnerability

CVE-2026-78961 is an authorization bypass flaw in Google Chrome Core that enables attackers to bypass web origin policy through social engineering and a compromised renderer process. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-78961 Overview

CVE-2026-78961 is an incorrect authorization vulnerability [CWE-863] in the Core component of Google Chrome versions prior to 152.0.7977.65. A remote attacker who has already compromised the renderer process can leverage social engineering to bypass the web origin policy through a crafted HTML page. Google's Chromium team rates the security severity as Medium. Exploitation requires both prior renderer compromise and user interaction, which raises the bar for successful attacks. Google addressed the issue in the Stable channel desktop update tracked in the Chromium Issue Tracker #497269030.

Critical Impact

Attackers who chain this flaw with a prior renderer compromise can bypass same-origin protections and access resources belonging to other web origins.

Affected Products

  • Google Chrome Desktop versions prior to 152.0.7977.65
  • Chromium-based browsers incorporating the affected Core component
  • All supported desktop platforms (Windows, macOS, Linux) running vulnerable builds

Discovery Timeline

  • 2026-08-25 - CVE-2026-78961 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-78961

Vulnerability Analysis

The vulnerability resides in the Core component of Chrome and stems from incorrect authorization enforcement [CWE-863]. Web browsers enforce the same-origin policy to prevent one web origin from reading or manipulating resources belonging to another. In this case, Chrome's authorization checks in Core do not adequately validate origin boundaries under specific conditions triggered from a compromised renderer.

A remote attacker must first compromise the renderer process, typically through a separate memory-safety or logic bug. The attacker then delivers a crafted HTML page and uses social engineering to convince the user to perform an action that triggers the authorization path. The bypass allows the attacker to read or influence data that should be isolated by the web origin policy.

The EPSS score is 0.335% at publication time, indicating a low modeled likelihood of near-term mass exploitation. The requirement for a prior renderer compromise and user interaction constrains opportunistic use in the wild.

Root Cause

Core fails to correctly authorize a cross-origin operation reachable from the renderer. The authorization check either trusts renderer-supplied state or misses a policy decision point before granting access. As a result, the browser process enforces a weaker origin boundary than the security model requires.

Attack Vector

Exploitation requires three preconditions. First, the attacker must already control the renderer process. Second, the victim must load a crafted HTML page under attacker influence. Third, the victim must be tricked through social engineering into an action that triggers the flawed authorization path. Successful chaining bypasses the web origin policy and exposes cross-origin data.

No verified public proof-of-concept is available. Refer to the Chromium Issue Tracker #497269030 and the Google Chrome Stable Update advisory for vendor details.

Detection Methods for CVE-2026-78961

Indicators of Compromise

  • Chrome browser processes running builds earlier than 152.0.7977.65 on managed endpoints
  • Renderer process crashes, unexpected child-process spawns, or sandbox escape telemetry preceding cross-origin data access
  • Outbound connections from Chrome to attacker-controlled domains hosting crafted HTML lures

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any builds below 152.0.7977.65.
  • Correlate browser exploitation telemetry (renderer crashes, JIT anomalies) with subsequent navigation to low-reputation domains.
  • Hunt for social engineering artifacts such as phishing emails, malvertising redirects, or fake update pages that funnel users to attacker HTML.

Monitoring Recommendations

  • Ingest browser and endpoint process telemetry into a centralized data lake for cross-source correlation.
  • Alert on Chrome child processes performing unusual file, network, or IPC activity outside normal browsing patterns.
  • Track enterprise Chrome update compliance through management tooling and generate exceptions for stale versions.

How to Mitigate CVE-2026-78961

Immediate Actions Required

  • Update Google Chrome to 152.0.7977.65 or later on all desktop endpoints.
  • Restart browser sessions after updating to ensure the patched binaries are loaded.
  • Validate update deployment through enterprise browser management or endpoint inventory tooling.

Patch Information

Google released the fix in the Chrome Stable channel desktop update. Deploy 152.0.7977.65 or later as documented in the Google Chrome Stable Update advisory. Chromium-based browser vendors (Edge, Brave, Opera, Vivaldi) should be tracked for their downstream releases incorporating the same fix.

Workarounds

  • Enforce site isolation and keep the Chrome sandbox enabled to raise the cost of the required renderer compromise.
  • Deploy user awareness reminders that address social engineering lures delivered through crafted web pages.
  • Restrict browsing to reputation-filtered destinations using DNS filtering or secure web gateways until patching completes.
bash
# Verify installed Chrome version on Linux/macOS endpoints
google-chrome --version
# Expected output should be 152.0.7977.65 or later

# Windows registry check for enterprise-managed Chrome version
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.